Prosecution Insights
Last updated: October 02, 2026
Application No. 18/873,476

RING SIGNATURE SYSTEM, TERMNAL, METHOD, AND PROGRAM

Non-Final OA §103
Filed
Dec 10, 2024
Priority
Jun 17, 2022 — nonprovisional of PCTJP2022024423
Examiner
CATTUNGAL, DEREENA T
Art Unit
2431
Tech Center
2400 — Computer Networks
Assignee
Nippon Telegraph and Telephone Corporation
OA Round
1 (Non-Final)
80%
Grant Probability
Favorable
1-2
OA Rounds
11m
Est. Remaining
99%
With Interview

Examiner Intelligence

Grants 80% — above average
80%
Career Allowance Rate
229 granted / 285 resolved
+22.4% vs TC avg
Strong +29% interview lift
Without
With
+29.4%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
21 currently pending
Career history
309
Total Applications
across all art units

Statute-Specific Performance

§101
8.0%
-32.0% vs TC avg
§103
59.9%
+19.9% vs TC avg
§102
15.4%
-24.6% vs TC avg
§112
13.8%
-26.2% vs TC avg
Black line = Tech Center average estimate • Based on career data from 285 resolved cases

Office Action

§103
CTNF 18/873,476 CTNF 92504 DETAILED ACTION Notice of Pre-AIA or AIA Status 07-03-aia AIA 15-10-aia 1.The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA. Claim Rejections - 35 USC § 103 07-20-aia AIA 2.The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. 07-21-aia AIA 3. Claim (s)1-2 and 6-8 are rejected under 35 U.S.C. 103 as being unpatentable over Masny (US Pub.No.2022/0353089) in view of Craige (US Pat.No.10,903,991) . 4. Regarding claim 1 Masny teaches a ring signature system comprising: a plurality of member terminals belonging to a ring signature group; and a verifier terminal that verifies a ring signature, wherein each member terminal among the member terminals includes a memory; and a processor coupled to the memory and configured to: generate a public key and a secret key of lattice-based cryptography as a verification key and a signature key, respectively, and generate a signature for a message by a linkable ring signature to which a signature is applied using the signature key of the member terminal and verification keys of the other member terminals, and the verifier terminal includes a memory; and a processor coupled to the memory and configured to: verify the signature using a verification key of the member terminal and the message (Fig.1 and Para:0040-0041 teaches at step 110, the generating device 102 can generate a public verification key and a private (secret) signing key. The private key can be used to generate digital signatures and the public key can be used to verify digital signatures. As the private key is used to generate signatures, it is important that it isn't leaked or otherwise disclosed to the attacker 106. After generating the cryptographic keys, at step 112 the generating device 102 can publish the public verification key. This publication can comprise making the verification key freely available to all devices in a particular network (e.g., the Internet), for example, by hosting the public key on a webserver. Alternatively, the generating device 102 can transmit the verification key to all other devices in the network, i.e., the signing device 104, the attacker 106, and the verifying device 108. At step 114, the generating device 102 can transmit the signing key to signing device 104. Possession of the signing key enables the signing device 104 to generate digital signatures. Para:0045-0049 teaches At step 118, the signing device 104 can generate a digital signature for the message m using the signing key. This digital signature (sometimes referred to as sig) may comprise two vectors: a challenge vector c, and a signature vector z. In brief, the signing device 104 uses the message, the public verification key, and a uniform random vector (sometimes referred to as a “masking vector”) “r” as the input to a hash function H to produce the challenge vector c. Using the challenge vector c, the private key, and the random vector r, the signing device 104 can produce the signature vector z. The digital signature may comprise both the challenge vector c and the signature vector z. At step 120, the signing device 104 can send the message and digital signature to the verifying device 108, via, a network . The signatures are based on a quantum safe, lattice-based cryptosystem, the attacker 106 has a vanishingly small probability of generating a fraudulent digital signature that can be verified correctly. At step 124, the attacker 106 can transmit its fraudulent message and attempted fraudulent signature to the verifying device 108. At step 126, the verifying device 108 can attempt to verify the message m and the fraudulent message. In short, the verifying device 108 can attempt to create its own challenge vector using the message, public verification key, and the digital signature. If the challenge vector matches the challenge vector c included in the digital signature, the verifying device 108 verifies that the signature is legitimate). Masny teaches all the above claimed limitations but fails to teach generate a signature for a message by a linkable ring signature to which a Schnorr signature is applied. Craige teaches generate a signature for a message by a linkable ring signature to which a Schnorr signature is applied (Col.4, lines.62-67 and Col.5, lines.1-4 teaches Schnorr signature). Therefore, to would have been obvious to one of the ordinary skills in the art before the effective filing date of the invention was filed to modify Masny to include generate a signature for a message by a linkable ring signature to which a Schnorr signature is applied as taught by Craige, performing secure communication using a Schnorr signature will result in faster computation and verification. 5. Regarding claim 2 Masny teaches the ring signature system, wherein the processor of each member terminal is configured to generate tag information of the member terminal using a hash value of a verification key list of the other member terminals and the signature key of the member terminal and generate a signature including the tag information (Para:0047-0049 teaches the signing device 104 can generate a digital signature for the message m using the signing key. This digital signature (sometimes referred to as sig) may comprise two vectors: a challenge vector c, and a signature vector z. In brief, the signing device 104 uses the message, the public verification key, and a uniform random vector (sometimes referred to as a “masking vector”) r as the input to a hash function H to produce the challenge vector c. Using the challenge vector c, the private key, and the random vector r, the signing device 104 can produce the signature vector z. The digital signature is accompanied by a label or tag may comprise both the challenge vector c and the signature vector z. At step 120, the signing device 104 can send the message and digital signature to the verifying device 108, via, for example, an unsecured network such as the Internet. At this time the attacker 106 may intercept the message and signature. At step 122, the attacker 106 may generate a fraudulent message and attempt to generate a fraudulent signature. The attacker 106 may attempt to break the signature system using the message m, signature (c, z), and the public key. Further, the attacker 106 may have access to a quantum computer capable of breaking conventional cryptosystems. However, because the signatures are based on a quantum safe, lattice-based cryptosystem, the attacker 106 has a vanishingly small probability of generating a fraudulent digital signature that can be verified correctly. At step 124, the attacker 106 can transmit its fraudulent message and attempted fraudulent signature to the verifying device 108. As stated above, the attacker 106 may produce and send a fraudulent message in order to defraud an owner or operator of the verifying device 108. At step 126, the verifying device 108 can attempt to verify the message m and the fraudulent message. In short, the verifying device 108 can attempt to create its own challenge vector using the message, public verification key, and the digital signature. If the challenge vector matches the challenge vector c included in the digital signature, the verifying device 108 verifies that the signature is legitimate) 6. Regarding claim 6 Masny teaches member terminal in a ring signature system including a plurality of member terminals belonging to a ring signature group and a verifier terminal verifying a ring signature, the member terminal comprising: a memory; and a processor coupled to the memory and configured to: generate a public key and a secret key of lattice-based cryptography as a verification key and a signature key, respectively; and generate a signature for a message by a linkable ring signature to which a Schnorr signature is applied using the signature key of the member terminal and verification keys of the other member terminals (see, the rejection for claim 1). 7. Regarding claim 7 Masny teaches method used for a ring signature system including a plurality of member terminals belonging to a ring signature group and a verifier terminal verifying a ring signature, the method comprising: generating, by each member terminal among the member terminals, a public key and a secret key of lattice-based cryptography as a verification key and a signature key, respectively; generating, by the each member terminal, a signature for a message by a linkable ring signature to which a Schnorr signature is applied using the signature key of the member terminal and verification keys of the other member terminals; and verifying, by the verifier terminal, the signature using a verification key of the member terminal and the message ((see, the rejection for claim 1). . 8. Regarding claim 8 Masny teaches non-transitory computer-readable recording medium storing a program causing a computer to perform the method of claim 7 (see, the rejection for claim 1). Allowable Subject Matter 07-43 9. Claims 3-5 are objected to as being dependent upon a rejected base claim 1, but would be allowable if rewritten in independent form including all of the limitations of the base claim and any intervening claims. Conclusion Any inquiry concerning this communication or earlier communications from the examiner should be directed to DEREENA T CATTUNGAL whose telephone number is (571)270-0506. The examiner can normally be reached Mon-Fri : 7:30 AM-5 PM EST. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Lynn Feild can be reached at 571-272-2092. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /DEREENA T CATTUNGAL/Primary Examiner, Art Unit 2431 Application/Control Number: 18/873,476 Page 2 Art Unit: 2431 Application/Control Number: 18/873,476 Page 3 Art Unit: 2431 Application/Control Number: 18/873,476 Page 4 Art Unit: 2431 Application/Control Number: 18/873,476 Page 5 Art Unit: 2431 Application/Control Number: 18/873,476 Page 6 Art Unit: 2431
Read full office action

Prosecution Timeline

Dec 10, 2024
Application Filed
Apr 03, 2026
Non-Final Rejection mailed — §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12743558
SECURE MODULE, ELECTRONIC PAYMENT TERMINAL, CORRESPONDING DETECTION METHOD
3y 4m to grant Granted Sep 22, 2026
Patent 12737489
DETERMINING LOCAL ADMINISTRATOR RIGHTS-RELATED DEPENDENCY RELATIONSHIPS USING ARTIFICIAL INTELLIGENCE TECHNIQUES
2y 7m to grant Granted Sep 15, 2026
Patent 12726348
EVENT ROUTING AND ENCRYPTION IN A MULTI-TENANT PROVIDER NETWORK
2y 8m to grant Granted Sep 01, 2026
Patent 12719929
Security for Groupcast Message in D2D Communication
4y 4m to grant Granted Aug 25, 2026
Patent 12719697
Method for digital signing and corresponding system
1y 10m to grant Granted Aug 25, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

1-2
Expected OA Rounds
80%
Grant Probability
99%
With Interview (+29.4%)
2y 9m (~11m remaining)
Median Time to Grant
Low
PTA Risk
Based on 285 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month